Security fixes are provided for the latest published major version.
| Version | Supported |
|---|---|
| 1.x | Yes |
| < 1.0 | No |
Do not open a public issue. Use GitHub's private vulnerability reporting for
PeerbitsSolution/audit-logger, or email security@peerbits.com. Do not include
PHI, credentials, client-identifying information, or production audit records
in the report.
Include the affected version, impact, minimal synthetic reproduction, and any known mitigations. Maintainers will acknowledge the report, investigate it, and coordinate disclosure and remediation based on severity.
This package:
- does not store PHI or validate whether an opaque ID is semantically de-identified;
- does not provide production persistence, authorization, encryption, or key management;
- provides tamper evidence, not tamper prevention or writer authentication;
- cannot establish HIPAA compliance by itself.
Production deployments must follow the Production Sink Guide and the deploying organization's risk analysis, policies, and legal obligations.